BleepingComputer reports that the Jewelbug hacker group has been running government and military espionage operations alongside cryptocurrency fraud, citing new findings from Symantec. The group is also tracked as Earth Alux and REF7707, and BleepingComputer describes it as China-based. The most concrete incident in the report is a webmail compromise affecting 15 government tenants during a campaign aimed at a country in the Middle East. According to BleepingComputer’s account of Symantec’s findings, Jewelbug gained write access to a shared webmail installation and placed a malicious script in a common template, allowing the code to run on login pages and mailbox views across those tenants. The script established a WebSocket connection to the attackers’ command-and-control server, exfiltrated webmail cookies, and checked the user’s email address to determine whether it belonged to a targeted government domain. BleepingComputer reports that higher-value targets were then shown a fake Adobe Flash update prompt that installed Windows malware, including the Antino backdoor and browser tooling. The tooling described in the report points to a broad collection and access operation rather than a one-off phishing campaign. Symantec tied Antino infections to Jewelbug infrastructure and gained visibility into the group’s command-and-control management platform, database, server logs, source code, and operator files, according to BleepingComputer. Jewelbug also uses XG-Web, described in the report as a remote-access and data-theft framework for managing campaigns and victim information. Another payload was a malicious browser extension for Chrome and Firefox named PDF Viewer, which BleepingComputer says was used to steal cookies and credentials, intercept traffic, inject JavaScript, and remotely expose browser functions. The scale reported by Symantec is material. BleepingComputer says the researchers found more than one million implant check-in rows, more than 580,000 stolen browser cookies, several thousand captured credentials, and more than 2,300 exfiltrated email bodies in Jewelbug’s victim database. The same infrastructure view also connected the espionage operation to what Symantec described as an “industrial-scale cryptocurrency fraud business,” according to BleepingComputer. Symantec found the espionage campaign and the crypto-fraud activity were conducted from the same control panel, which is why the report raises the possibility that Jewelbug may also operate as a hack-for-hire group seeking profit from cybercrime. The espionage targeting was not limited to one region. BleepingComputer reports that Jewelbug targeted government and military organizations across the Middle East, Southeast Asia, and South Asia, as well as organizations in critical sectors including defense, telecommunications, education, and aviation. Symantec’s runtime logs also showed roughly 1.1 million geolocation events against about 4,300 distinct source IP addresses, according to the report. The cited activity included about 87,200 connections from a Southeast Asian country involving state telecom and military networks, about 53,100 from a Middle Eastern country across national-carrier ranges including Starlink-connected addresses in the capital, and about 15,000 from a second Southeast Asian country that included government ministry infrastructure. Who benefits: Jewelbug benefits from reusable infrastructure that can support espionage and fraud operations. Security teams benefit from the operational detail in Symantec’s findings, particularly the webmail attack path and named malware families. Who's exposed: Government, military, telecommunications, defense, education, and aviation organizations are the exposed groups identified in the report. The clearest exposure described is for multi-tenant webmail environments where a shared component can affect many accounts or organizations at once.